Support the execution of technology risk assessments, including System Risk Assessments, Risk and Control Self-Assessments, and project / new initiative assessments
Supply to risk oversight of cloud modernization initiatives, including migration to AWS, cloud-native architectures, and associated risks (e.g., resilience, configuration, security)
Support risk activities related to AI governance and AI-enabled solutions, including consistency to policy requirements, use case approval processes, model and data risk considerations, and monitoring of AI-related risks
Assist in the identification and assessment of risks associated with blockchain technologies, including tokenization models, integration with traditional financial systems, and evolving market structure considerations
Support risk coverage of initiatives involving digital asset infrastructure and workflows, including areas such as collateral management, liquidity movement, and interaction between on-chain and traditional systems
Chip in to the development and maintenance of technology risk metrics, Key Risk Indicators (KRIs), and risk dashboards, enabling more effective monitoring and reporting
Support the delivery of risk reporting and insights to governance forums, including contributions to risk assessment results and risk profile updates
Partner with product engineering, infrastructure, and product teams to provide actionable risk mentorship and effective challenge on control develop and implementation
Support incident and issue management activities, including analysis of technology incidents (e.g., outages, security events) and identification of thematic risks and control gaps
Assist in embedding technology risk considerations into the product development lifecycle (PDLC), organisational change, and operational processes, including emerging areas such as automated/AI-assisted development
Give to initiatives to improve Nasdaq’s technology risk frameworks, methodologies, and tooling, including integration of risk processes with modern engineering and cloud environments
Collaborate with multi-functional risk and assurance teams (Information Security, Internal Audit, Compliance, Legal, Global Tech) to support a coordinated approach to risk management.